Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Big Microsoft 365 price increases coming next year

      Big Microsoft price increases coming next year

      5 December 2025
      Vodacom to take control of Safaricom in R36-billion deal - Shameel Joosub

      Vodacom to take control of Safaricom in R36-billion deal

      4 December 2025
      Black Friday goes digital in South Africa as online spending surges to record high

      Black Friday goes digital in South Africa as online spending surges to record high

      4 December 2025
      BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

      BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

      4 December 2025
      'Get it now': Takealot in new instant deliveries pilot

      ‘Get it now’: Takealot in new instant deliveries pilot

      4 December 2025
    • World
      Amazon and Google launch multi-cloud service for faster connectivity

      Amazon and Google launch multi-cloud service for faster connectivity

      1 December 2025
      Google makes final court plea to stop US breakup

      Google makes final court plea to stop US breakup

      21 November 2025
      Bezos unveils monster rocket: New Glenn 9x4 set to dwarf Saturn V

      Bezos unveils monster rocket: New Glenn 9×4 set to dwarf Saturn V

      21 November 2025
      Tech shares turbocharged by Nvidia's stellar earnings

      Tech shares turbocharged by stellar Nvidia earnings

      20 November 2025
      Config file blamed for Cloudflare meltdown that disrupted the web

      Config file blamed for Cloudflare meltdown that disrupted the web

      19 November 2025
    • In-depth
      Jensen Huang Nvidia

      So, will China really win the AI race?

      14 November 2025
      Valve's Linux console takes aim at Microsoft's gaming empire

      Valve’s Linux console takes aim at Microsoft’s gaming empire

      13 November 2025
      iOCO's extraordinary comeback plan - Rhys Summerton

      iOCO’s extraordinary comeback plan

      28 October 2025
      Why smart glasses keep failing - no, it's not the tech - Mark Zuckerberg

      Why smart glasses keep failing – it’s not the tech

      19 October 2025
      BYD to blanket South Africa with megawatt-scale EV charging network - Stella Li

      BYD to blanket South Africa with megawatt-scale EV charging network

      16 October 2025
    • TCS
      TCS+ | How Cloud on Demand helps partners thrive in the AWS ecosystem - Odwa Ndyaluvane and Xenia Rhode

      TCS+ | How Cloud On Demand helps partners thrive in the AWS ecosystem

      4 December 2025
      TCS | MTN Group CEO Ralph Mupita on competition, AI and the future of mobile

      TCS | Ralph Mupita on competition, AI and the future of mobile

      28 November 2025
      TCS | Dominic Cull on fixing South Africa's ICT policy bottlenecks

      TCS | Dominic Cull on fixing South Africa’s ICT policy bottlenecks

      21 November 2025
      TCS | BMW CEO Peter van Binsbergen on the future of South Africa's automotive industry

      TCS | BMW CEO Peter van Binsbergen on the future of South Africa’s automotive industry

      6 November 2025
      TCS | Why Altron is building an AI factory - Bongani Andy Mabaso

      TCS | Why Altron is building an AI factory in Johannesburg

      28 October 2025
    • Opinion
      Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

      Your data, your hardware: the DIY AI revolution is coming

      20 November 2025
      Zero Carbon Charge founder Joubert Roux

      The energy revolution South Africa can’t afford to miss

      20 November 2025
      It's time for a new approach to government IT spend in South Africa - Richard Firth

      It’s time for a new approach to government IT spend in South Africa

      19 November 2025
      How South Africa's broken Rica system fuels murder and mayhem - Farhad Khan

      How South Africa’s broken Rica system fuels murder and mayhem

      10 November 2025
      South Africa's AI data centre boom risks overloading a fragile grid - Paul Colmer

      South Africa’s AI data centre boom risks overloading a fragile grid

      30 October 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » News » Vodafone is said to have found hidden ‘backdoors’ in Huawei gear

    Vodafone is said to have found hidden ‘backdoors’ in Huawei gear

    By Agency Staff30 April 2019
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp
    Vodafone Group CEO Nick Read

    For months, Huawei has faced US allegations that it flouted sanctions on Iran, attempted to steal trade secrets from a business partner and has threatened to enable Chinese spying through the telecommunications networks it’s built across the West.

    Now Vodafone Group has acknowledged to Bloomberg that it found vulnerabilities going back years with equipment supplied by Shenzhen-based Huawei for the carrier’s Italian business. While Vodafone says the issues were resolved, the revelation may further damage the reputation of a major symbol of China’s global technology prowess.

    Europe’s biggest phone company identified hidden backdoors in the software that could have given Huawei unauthorised access to the carrier’s fixed-line network in Italy, a system that provides Internet service to millions of homes and businesses, according to Vodafone’s security briefing documents from 2009 and 2011 seen by Bloomberg, as well as people involved in the situation.

    Huawei has repeatedly denied that it creates backdoors and says it’s not beholden to Beijing

    Vodafone asked Huawei to remove backdoors in home Internet routers in 2011 and received assurances from the supplier that the issues were fixed, but further testing revealed that the security vulnerabilities remained, the documents show. Vodafone also identified backdoors in parts of its fixed-access network known as optical service nodes, which are responsible for transporting Internet traffic over optical fibres, and other parts called broadband network gateways, which handle subscriber authentication and access to the Internet, the people said. The people asked not to be identified because the matter was confidential.

    A backdoor, in cybersecurity terms, is a method of bypassing security controls to access a computer system or encrypted data. While backdoors can be common in some network equipment and software because developers create them to manage the gear, they can be exploited by attackers. In Vodafone’s case, the risks included possible third-party access to a customer’s PC and home network, according to the internal documents.

    Espionage

    The Trump administration in the US, arguing such end-runs around security in Huawei’s equipment could invite espionage by the Chinese state, is trying to persuade Western allies to block the company from the next generation of mobile networks. Huawei has repeatedly denied that it creates backdoors and says it’s not beholden to Beijing.

    Huawei’s ability to continue winning contracts from London-based Vodafone, despite the carrier’s security concerns, underscores the challenge facing the US as it tries to hinder the world’s top telecoms equipment vendor and number two supplier of smartphones. Huawei is vying against a stable of Western companies including Nokia and Ericsson to roll out 5G wireless networks.

    Vodafone has defended Huawei against the US onslaught, which has placed Europe — Huawei’s largest market outside China — in the middle of a trade battle between two superpowers. At stake is leadership in key areas, principally 5G technology that’s designed to support the Internet of things and new applications in industries spanning automotive, energy to healthcare. Vodafone CEO Nick Read has joined peers in publicly opposing any bans on Huawei from 5G roll-outs, warning of higher costs and delays. The defiance shows that countries across Europe are willing to risk rankling the US in the name of 5G preparedness.

    In a statement, Vodafone said it found vulnerabilities with the routers in Italy in 2011 and worked with Huawei to resolve the issues that year. There was no evidence of any data being compromised, it said. The carrier also identified vulnerabilities with the Huawei-supplied broadband network gateways in Italy in 2012 and said those were resolved the same year. Vodafone also said it found records that showed vulnerabilities in several Huawei products related to optical service nodes. It didn’t provide specific dates and said the issues were resolved. It said it couldn’t find evidence of historical vulnerabilities in routers or broadband network gateways beyond Italy.

    “In the telecoms industry, it is not uncommon for vulnerabilities in equipment from suppliers to be identified by operators and other third parties,” the company said. “Vodafone takes security extremely seriously and that is why we independently test the equipment we deploy to detect whether any such vulnerabilities exist. If a vulnerability exists, Vodafone works with that supplier to resolve it quickly.”

    Vodafone takes security extremely seriously and that is why we independently test the equipment we deploy to detect whether any such vulnerabilities exist

    In a statement, Huawei said it was made aware of historical vulnerabilities in 2011 and 2012 and they were addressed at the time.

    However, Vodafone’s account of the issue was contested by people involved in the security discussions between the companies. Vulnerabilities in both the routers and the fixed access network remained beyond 2012 and were also present in Vodafone’s businesses in the UK, Germany, Spain and Portugal, said the people. Vodafone stuck with Huawei because the services were competitively priced, they said.

    While backdoors are common in home routers, they are usually fixed by manufacturers once disclosed, said Eric Evenchick, principal research consultant at Atredis Partners, a US-based cybersecurity firm. Evenchick called the situation with Huawei’s equipment “very concerning”.

    Founded in 1987, Huawei entered the European market in 2000. Landmark contracts with Britain’s BT Group and Norway’s TeliaSonera helped Huawei win market share from — and eventually surpass — Nokia and Ericsson.

    Wi-Fi routers

    Vodafone started buying Wi-Fi routers from Huawei in 2008 for its Italian business and, later, for the UK, Germany, Spain and Portugal.

    Vodafone managers had concerns with the security of the routers almost right away. They were the topic of an internal presentation from October 2009 that pointed to 26 open bugs in the routers, six identified as “critical” and nine as “major”. Vodafone said in the report that Huawei would need to remove or inhibit a so-called telnet service — a protocol used to control devices remotely — that the carrier said was a backdoor giving Huawei access to sensitive data.

    In January 2011, Vodafone Italy started a deeper probe of the routers, according to an April report from the year. Security testing by an independent contractor identified the telnet backdoor as the greatest concern, posing risks including giving unauthorised access to Vodafone’s broader wide-area network. Vodafone noted that it’s an industry practice by some router manufacturers to use a telnet service to manage their equipment, but the company said it didn’t allow this.

    The document chronicles a two-month period during which Vodafone’s Italian unit discovered the telnet service, demanded its removal by Huawei and received assurances from the supplier that the problem was fixed. After further testing, Vodafone found that the telnet service could still be launched.

    Vodafone said Huawei then refused to fully remove the backdoor, citing a manufacturing requirement. Huawei said it needed the telnet service to configure device information and conduct tests including on Wi-Fi, and offered to disable the service after taking those steps, according to the document.

    Huawei’s apparent reluctance only amplified concerns that were circulating even then that the company might pose a security threat to customers.

    Unfortunately for Huawei, the political background means that this event will make life even more difficult for them…

    “Unfortunately for Huawei, the political background means that this event will make life even more difficult for them in trying to prove themselves an honest vendor,” Vodafone said in the April 2011 document authored by its chief information security officer at the time, Bryan Littlefair. He noted that Vodafone had made a recent security visit to Shenzhen and said he was surprised Huawei hadn’t given the matter a greater priority.

    “What is of most concern here is that actions of Huawei in agreeing to remove the code, then trying to hide it, and now refusing to remove it as they need it to remain for ‘quality’ purposes,” Littlefair wrote.

    Huawei declined to comment on the concerns raised by Littlefair. Littlefair didn’t respond to requests for comment.

    ‘Characteristics of backdoors’

    “There’s no specific way to tell that something is a backdoor and most backdoors would be designed to look like a mistake,” said Stefano Zanero, an associate professor of computer security at Politecnico di Milano University. “That said, the vulnerabilities described in the Vodafone reports from 2009 and 2011 have all the characteristics of backdoors: deniability, access and a tendency to be placed again in subsequent versions of the code,” he said.

    Huawei called software vulnerabilities “an industry-wide challenge”. In a statement, it said: “Like every ICT vendor we have a well-established public notification and patching process, and when a vulnerability is identified we work closely with our partners to take the appropriate corrective action.”

    Some telecoms companies have taken steps to limit Huawei’s exposure from the most sensitive parts of their networks

    Huawei has expanded its relationship with Vodafone well beyond routers and is now its fourth largest supplier behind Apple, Nokia and Ericsson. Huawei’s gear is found across Vodafone’s wireless networks in Europe; in the UK, equipment from Huawei accounts for about one-third of the radio-access network, a critical piece of the infrastructure.

    Some telecoms companies have taken steps to limit Huawei’s exposure from the most sensitive parts of their networks, amid the added government scrutiny. In January, Vodafone’s CEO, Read, said the company had paused purchases of Huawei equipment for the core of its mobile networks in Europe, citing too much “noise” around the situation.

    Still, carriers including Vodafone are fighting against the threat of Huawei being banned in Europe because they’ve come to rely so heavily on the supplier. Abandoning Huawei for 5G, with Europe already lagging behind China and the US, could force them to rip out the supplier’s 4G gear, a process that could take years and cost billions of dollars.  — Reported by Daniele Lepido, (c) 2019 Bloomberg LP



    Huawei Nick Read top Vodafone
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleHuawei is being held to an impossible standard
    Next Article CIVH’s Vumatel acquisition approved, with conditions

    Related Posts

    Vodacom to take control of Safaricom in R36-billion deal - Shameel Joosub

    Vodacom to take control of Safaricom in R36-billion deal

    4 December 2025
    Huawei makes the season brighter with service offers that truly care

    Huawei makes the season brighter with service offers that truly care

    3 December 2025
    Samsung's first trifold smartphone is here

    Samsung’s first trifold smartphone is here

    2 December 2025
    Company News
    AI is not a technology problem - iqbusiness

    AI is not a technology problem – iqbusiness

    5 December 2025
    Telcos are sitting on a data gold mine - but few know what do with it - Phillip du Plessis

    Telcos are sitting on a data gold mine – but few know what do with it

    4 December 2025
    Unlock smarter computing with your surface Copilot+ PC

    Unlock smarter computing with your Surface Copilot+ PC

    4 December 2025
    Opinion
    Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

    Your data, your hardware: the DIY AI revolution is coming

    20 November 2025
    Zero Carbon Charge founder Joubert Roux

    The energy revolution South Africa can’t afford to miss

    20 November 2025
    It's time for a new approach to government IT spend in South Africa - Richard Firth

    It’s time for a new approach to government IT spend in South Africa

    19 November 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Big Microsoft 365 price increases coming next year

    Big Microsoft price increases coming next year

    5 December 2025
    AI is not a technology problem - iqbusiness

    AI is not a technology problem – iqbusiness

    5 December 2025
    Vodacom to take control of Safaricom in R36-billion deal - Shameel Joosub

    Vodacom to take control of Safaricom in R36-billion deal

    4 December 2025
    Black Friday goes digital in South Africa as online spending surges to record high

    Black Friday goes digital in South Africa as online spending surges to record high

    4 December 2025
    © 2009 - 2025 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}